Scoring methodology
Published in full so a report can be defended to an auditor or regulator.
How the score is produced
- Every transfer is attributed to a counterparty entity and its risk category.
- Flows are split into inbound and outbound. Within each direction the share of value transacted with each category is computed.
- A category contributes
penalty x min(1, (share / saturation) ^ 0.5)to that direction's penalty. The square root keeps the curve concave: small exposure to sanctions still matters, large exposure to a regulated exchange stays cheap. - Direction penalty = largest single contribution + 35% of the rest, capped at 99. Score = 100 - penalty, clamped to 1-100, so lower means riskier.
- Zero tolerance: any non-zero flow with a severity-10 category (sanctioned, terrorism financing, CSAM) sets that direction to 1 regardless of size, because sanctions liability does not scale with the amount transferred.
- The overall score averages both directions, unless severity 9-10 exposure is present, in which case the worse direction is used. An address that is itself designated always scores 1.
| Score | Risk level |
|---|---|
| 80 - 100 | Low |
| 60 - 79 | Medium |
| 40 - 59 | High |
| 20 - 39 | Severe |
| 1 - 19 | Critical |
Risk categories (20)
| Category | Severity | Penalty | Saturation |
|---|---|---|---|
| Sanctioned entity or designated address sanctioned |
10 | 99.0 | 0.1% |
| Terrorism financing terrorism_financing |
10 | 99.0 | 0.1% |
| Child sexual abuse material child_abuse_material |
10 | 99.0 | 0.1% |
| Ransomware operator or affiliate ransomware |
9 | 90.0 | 0.1% |
| Darknet marketplace darknet_market |
9 | 90.0 | 0.1% |
| Mixing or anonymising service mixer |
8 | 80.0 | 3.0% |
| Proceeds of hacks and exploits stolen_funds |
8 | 80.0 | 3.0% |
| Scam, phishing or investment fraud scam |
7 | 70.0 | 3.0% |
| Fraud shop / stolen data vendor fraud_shop |
7 | 70.0 | 3.0% |
| Exchange with weak or absent KYC high_risk_exchange |
6 | 60.0 | 20.0% |
| Unlicensed peer-to-peer broker unlicensed_p2p |
5 | 50.0 | 20.0% |
| Gambling or betting service gambling |
5 | 50.0 | 20.0% |
| Cross-chain bridge bridge |
3 | 12.0 | 50.0% |
| Decentralised finance protocol defi |
2 | 4.0 | 60.0% |
| Unattributed address unknown |
2 | 4.0 | 60.0% |
| Regulated exchange or VASP exchange |
1 | 2.0 | 60.0% |
| Mining pool mining |
1 | 2.0 | 60.0% |
| Merchant or payment processor merchant |
1 | 2.0 | 60.0% |
| Regulated custodian custodian |
1 | 2.0 | 60.0% |
| Token contract token_contract |
1 | 2.0 | 60.0% |
Risk indicators (54)
Entity
| SANCTIONS_DIRECT | Direct sanctions exposure |
| TERRORISM_FINANCING | Terrorism financing exposure |
| CSAM_EXPOSURE | Child abuse material exposure |
| RANSOMWARE_EXPOSURE | Ransomware exposure |
| DARKNET_EXPOSURE | Darknet marketplace exposure |
| MIXER_EXPOSURE | Mixing service exposure |
| STOLEN_FUNDS_EXPOSURE | Stolen funds exposure |
| SCAM_EXPOSURE | Scam and fraud exposure |
| FRAUD_SHOP_EXPOSURE | Fraud shop exposure |
| HIGH_RISK_VASP | High-risk exchange exposure |
| UNLICENSED_P2P | Unlicensed P2P broker exposure |
| GAMBLING_EXPOSURE | Gambling service exposure |
| SUBJECT_DESIGNATED | Subject is a designated entity |
| SUBJECT_ILLICIT_ATTRIBUTION | Subject attributed to an illicit service |
| SANCTIONS_INDIRECT | Indirect sanctions nexus |
| UNATTRIBUTED_MAJORITY | Majority unattributed counterparties |
| NESTED_SERVICE | Possible nested service |
| CLUSTER_EXPANSION | Expansion into newly seen clusters |
| UNIDENTIFIED_VOLUME | Value concentrated in unlabelled clusters |
Behaviour
| HIGH_VELOCITY | High transaction velocity |
| RAPID_PASSTHROUGH | Rapid pass-through of funds |
| PEEL_CHAIN | Peel chain pattern |
| STRUCTURING | Structuring below reporting threshold |
| ROUND_AMOUNTS | Repeated round-value transfers |
| DORMANT_REACTIVATION | Dormant address reactivated |
| HIGH_OUTFLOW_RATIO | Funds forwarded almost in full |
| ZERO_BALANCE_PASSTHROUGH | Pass-through address |
| MANY_COUNTERPARTIES | Unusually broad counterparty set |
| SINGLE_SOURCE_DEPENDENCE | Concentrated funding source |
| LARGE_SINGLE_TRANSFER | Large single transfer |
| PROFILE_DEVIATION | Deviation from stated customer profile |
| OPENING_DEPOSIT | Opening deposit inconsistent with stated identity |
| MANY_TO_ONE_WALLETS | Many-to-one inbound wallet shape |
| NEW_ADDRESS_HIGH_VOLUME | New address with high volume |
| MULTI_HOP_LAYERING | Layering across single-use counterparties |
| DUST_INBOUND | Dusting activity |
| BRIDGE_HEAVY | Heavy cross-chain bridging |
| INACTIVE_ADDRESS | Limited activity window |
| MEMPOOL_UNCONFIRMED | Unconfirmed Bitcoin transactions |
Geography
| SANCTIONED_JURISDICTION | Sanctioned jurisdiction exposure |
| HIGH_RISK_JURISDICTION | High-risk jurisdiction exposure |
| FATF_GREYLIST | FATF grey list jurisdiction exposure |
| OFFSHORE_SECRECY | Offshore secrecy jurisdiction exposure |
| JURISDICTION_DIVERSITY | Wide jurisdictional spread |
Regulatory
| SINGLE_TRANSFER_LIMIT | Single transfer limit breached |
| CUMULATIVE_VOLUME_LIMIT | Cumulative volume limit breached |
| TRAVEL_RULE_APPLICABLE | Travel Rule transfers present |
| TRAVEL_RULE_GAP | Counterparty cannot meet the Travel Rule |
| UNHOSTED_WALLET_MAJORITY | Majority unhosted counterparties |
Defi
| STABLECOIN_CONCENTRATION | Stablecoin concentration |
| FLASH_LOAN_PATTERN | Protocol round trips inside minutes |
| LIQUIDITY_POOL_CONCENTRATION | Liquidity pool concentration |
| CROSS_CHAIN_SWAPS | Cross-chain and swap routing |
Indirect
| INDIRECT_SEVERE_EXPOSURE | Severe exposure at a distance |
Jurisdiction risk (48)
| Jurisdiction | Risk | Flags |
|---|---|---|
| North Korea KP | 10 | FATF call for action |
| Iran IR | 10 | FATF call for action |
| Syria SY | 10 | FATF grey list |
| Myanmar MM | 10 | FATF call for action |
| Afghanistan AF | 8 | |
| Russia RU | 7 | |
| Belarus BY | 7 | |
| Venezuela VE | 6 | FATF grey list |
| Panama PA | 5 | offshore secrecy |
| Seychelles SC | 5 | offshore secrecy |
| British Virgin Islands VG | 5 | FATF grey list offshore secrecy |
| Cayman Islands KY | 4 | offshore secrecy |
| Curacao CW | 4 | offshore secrecy |
| Unattributed -- | 3 | |
| United Arab Emirates AE | 3 | |
| Malta MT | 3 | |
| Cyprus CY | 3 | |
| Angola AO | 3 | FATF grey list |
| Bosnia and Herzegovina BA | 3 | FATF grey list |
| Bulgaria BG | 3 | FATF grey list |
| Bermuda BM | 3 | offshore secrecy |
| Bolivia BO | 3 | FATF grey list |
| Belize BZ | 3 | offshore secrecy |
| Democratic Republic of the Congo CD | 3 | FATF grey list |
| Cote d'Ivoire CI | 3 | FATF grey list |
| Cameroon CM | 3 | FATF grey list |
| Haiti HT | 3 | FATF grey list |
| Iraq IQ | 3 | FATF grey list |
| Kenya KE | 3 | FATF grey list |
| Kuwait KW | 3 | FATF grey list |
| Lao PDR LA | 3 | FATF grey list |
| Lebanon LB | 3 | FATF grey list |
| Monaco MC | 3 | FATF grey list |
| Nepal NP | 3 | FATF grey list |
| Papua New Guinea PG | 3 | FATF grey list |
| South Sudan SS | 3 | FATF grey list |
| Vietnam VN | 3 | FATF grey list |
| Yemen YE | 3 | FATF grey list |
| Estonia EE | 2 | |
| Lithuania LT | 2 | |
| Luxembourg LU | 1 | |
| Germany DE | 1 | |
| France FR | 1 | |
| United Kingdom GB | 1 | |
| Switzerland CH | 1 | |
| Singapore SG | 1 | |
| United States US | 1 | |
| Japan JP | 1 |
Data sources
Live chain data comes from Alchemy for Ethereum, BSC, Base, Optimism, Polygon,
Arbitrum and Solana when ALCHEMY_API_KEY is set (same key; enable
each network in the dashboard). QuickNode is the per-chain failover when
QUICKNODE_<CHAIN>_URL is set. Blockscout is the keyless
path and failover. TronGrid covers TRX and TRC-20. Solana prefers Alchemy or
QuickNode, then the public RPC. mempool.space is used for Bitcoin
(paginated). Zero-value native transactions are kept so contract interaction
without ETH is still visible. Native USD uses a CoinGecko daily close at the
transfer date when the chart is available. Fiat-referenced tokens peg at 1
only when the contract or mint matches a stored issuer list (USDT/USDC/DAI
and a handful of peers per chain); a spoofed ticker is left unpriced.
Wrapped natives (WETH, WBTC) reuse the live ETH/BTC close. Other tokens
use the indexer's spot rate or stay unpriced. Geography indicators read a
compact FATF snapshot (call for action and increased monitoring as of
19 June 2026) stored in SQLite, not a live FATF feed. Travel Rule
($1,000) and CTR ($10,000) floors live in that same table. If Blockscout fails and
ETHERSCAN_API_KEY is set, Etherscan v2 is used as a last
failover. An indexer error with no failover is returned as a failure, not
replaced with generated transfers. An address with no activity is scored on
that empty window. Flux hop 1 is the subject's own transfers; hop 2 and 3
are a live indexer walk of the top counterparties (hosted exchanges,
custodians, merchants, high-risk exchanges and mixers are terminals —
out of sight, not a clean end of trail). Each report states the indexer in
its provenance block. Flux reports include a server-rendered transfer diagram:
Source 3 → Source 2 → Hop 1 sources → Subject → Hop 1 destinations → Hop 2 →
Hop 3+, nodes ordered by first_seen, edge thickness by USD value.
The label set holds 2463 entities, including a public overlay
of widely documented addresses. Entries marked
public are documented addresses. Entries marked
synthetic exist so the scoring models can be unit-tested; they
are not applied unless a live counterparty matches a seeded address.
Unlabelled counterparties stay unknown.
Cross-product glossary
Shared score scales, provenance data_source values, observed vs
modelled fields, EVM failover order, and typology family IDs live in the
repository file docs/compute-glossary.md.